Your always-on compliance officer, priced per provider.
Holdmark Health continuously scans chart notes, billing files, and policy documents for HIPAA and payer-documentation gaps — generating audit-ready reports on demand, watching HHS and state-privacy changes for you, and pushing bite-sized training to your front desk and clinical staff.
No compliance officer needed.
Solo and small-group medical, dental, and mental-health practices. Replaces the binder nobody updates — and the $80K–$120K generalist you can’t justify.
holdmark.app / practice
Today · chart-note audit
- high
Unsigned progress note · visit 9/12
Pt chart · encounter #04812
- med
LCD coverage criterion · CPT 99214
Billing file · claim #C-9241
- low
Acknowledged consent form · annual
Pt chart · encounter #04793
1 new HHS rule · effective in 21 days — flagged for owner review
Replaces the patchwork of
- Hand binders nobody updates
- Quarterly consultant retainers
- Separate training, audit, and breach tools
- Spreadsheets of policy versions
What it does
The most manual parts of compliance, handled.
Five workflows that today live across separate tools — or, more often, in a binder nobody updates. Holdmark bundles them into one dashboard for a fraction of a full-time compliance hire.
Built for
Practices that can’t justify a $80K compliance hire, but can’t skip compliance either.
Medical practices
One to four providers — primary care, specialty clinics, occupational health, urgent care.
Dental practices
Single-chair and small-group dental groups handling insurance, x-ray retention, and patient portal access.
Mental-health practices
Therapy groups, psychiatry, and integrated behavioral-health practices — where documentation standards differ from medical.
What practice owners say
Built for practices just like yours.
A solo therapist, a four-operatory dental office, and a three-provider pediatric clinic — each with a different compliance shape, each on Holdmark.
“I don't have time to track every HIPAA-evidence change between sessions. Holdmark does, and the monthly report lands before my last client leaves.”
Dr. M. Alvarez, LCSW
Solo therapist · 1 provider · Brooklyn, NY
“Audit-ready packets used to mean a week of digging through inboxes. Now I email one PDF and move on to my next op.”
K. Pham, DDS
Dental office owner · 4 ops · San Jose, CA
“Role-based training and policy versioning was the part I kept dropping. The dashboard flags what lapsed for which staff, so I close the gap the same week.”
Dr. R. Okafor, FAAP
Pediatric clinic owner · 3 providers · Atlanta, GA
Regulatory intelligence
The volume solo practices simply can’t track by hand.
In the last twelve months the HHS breach-notification rule was updated, multiple state privacy acts took effect, and dozens of payer documentation requirements shifted. A solo practice owner cannot read every Federal Register notice — Holdmark reads them for you and surfaces what actually changes your week.
- 100+
- HHS / OCR updates per year
- 50+
- State privacy bills introduced
- 1,400+
- Payer policy revisions
Regulatory activity
Filtered for solo & small-group practices · last 30 days
Today
HHS / OCR
Breach-notification rule — proposed amendment to 60-day trigger window
Impacts your practice · federal
2 days
CA Attorney General
CCPA narrow amendment to health-data exemption for small practices
Impacts your practice · state
1 week
Noridian
LCD for joint injections updated — coverage criteria #3 revised
Impacts your practice · payer
2 weeks
ONC
Information-blocking enforcement discretion extended to Q1 2026
Impacts your practice · federal
3 weeks
NY DOH
Mental-health record access deadlines — companion to existing statute
Impacts your practice · state
+ 29 more updates in this window · see dashboard for the full list
If something goes wrong
A guided workflow, from first signal to closed file.
The HHS breach-notification clock is unforgiving — sixty days from discovery for federal notice, faster for some states. Holdmark drafts the notifications, sets the deadlines against your discovery date, and tracks every required step so nothing quietly slips.
Day 0
Discovery logged, scope contained
Document what was accessed, by whom, and what was exposed. Holdmark pre-fills the HIPAA breach-risk assessment.
Day 1–10
Investigation + notification prep
Affected individuals are identified; notification drafts are ready. Holdmark tracks state-specific timelines (e.g., CA, NY, TX) on top of the federal clock.
Day 60
Federal notice deadline
HHS submission ready, media notice prepared for breaches affecting 500+. Templates already drafted in your voice.
Pricing
Per provider. Same band you already pay for software, not staff.
Three plans tuned to the shape of a small practice. Most practices fit in the middle one — switch up or down at any time.
Single provider, baseline coverage
- Continuous chart-note & policy audit
- On-demand audit-ready report exports
- HHS + state regulatory feed (your scope)
- Annual staff training refresh
The most common shape — small multi-provider practice
- Everything in Solo, plus:
- Breach-response workflow & templates
- Quarterly staff training + role-tracked completion
- Multi-state privacy rules (where relevant)
- Priority inbox for rule-change questions
3+ providers, multi-site, or payer-heavy billers
- Everything in Practice, plus:
- Per-site audit packets
- Custom payer policy monitoring
- Dedicated onboarding with a compliance lead
- Live phone escalation during incidents
Holdmark is sold direct. Reach out and we’ll match the right plan to your provider count, specialty, and payer mix.
FAQ
Questions practices ask before signing on.
Don’t see yours? Email holdmark-health@polsia.app and we’ll write back the same day.
Replace the binder, not the practice.
Tell us about your practice — provider count, specialty, where you’re licensed, and what’s on the regulatory radar for you this quarter. We’ll come back with the plan that fits and a trial scope.